Skip to content
KaryaYogi
Leave & CalendarHoliday bridges, leave balances, school… Pay & MoneySalary calculator, 7th CPC matrix, DA… Service & BenefitsAPAR windows, LTC blocks, CGHS, conduct… Planning & ProductivityTasks, notes, voice memos, journal,… WellnessSteps and activity rings, weight, habits,… Personal UtilityDocument scanner, secure vault, world time,… Privacy & SettingsApp lock, encrypted local backup, emergency…
View all 74 tools →
Experience Security What’s New Trust
Open Portal Download

Tools

Leave & Calendar Pay & Money Service & Benefits Planning & Productivity Wellness Personal Utility Privacy & Settings All 74 tools

Explore

Experience Security What’s New Privacy Policy Delete Account
Open Portal Download
Home / Legal / Responsible Disclosure

Responsible Disclosure

Found a vulnerability? Here is how to report it safely and what happens next.

Last updated: 4 July 2026

On this page

  • About This Policy
  • Our Commitment to You (Safe Harbour)
  • What Is In Scope
  • What Is Out of Scope
  • Rules for Good-Faith Testing
  • How to Report a Vulnerability
  • What You Can Expect From Us
  • Recognition — and No Bounty
  • Coordinated Disclosure — Do Not Disclose Until Fixed
  • How This Fits Our Data Protection Duties
  • Contact and Related Pages

About This Policy

KaryaYogi is a private planning and productivity Android app for officers, published by KaryaYogi. It is not an official Government of India system. It does not replace or connect to eOffice, HRMS, APAR, pay systems, sanction files, GeM, GFR, CGHS, DoPT or any other authorised system of record. The tools in the app produce private drafts and estimates only; nothing is filed or submitted officially.

We take the security of the app and the optional web portal seriously. This page explains how to report a security vulnerability to us in good faith, what we consider in scope, and how we will respond. It is written for security researchers, but any user who notices a security problem is welcome to use the same process.

The single point of contact for all security reports is support@karyayogi.in. Please use this address rather than our support or grievance channels for anything security-related.

Our Commitment to You (Safe Harbour)

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will treat your work as authorised testing. We will not ask law enforcement to investigate you, and we will not pursue civil action against you, for security research that stays within the scope and rules set out on this page.

This safe-harbour intent applies only to testing you carry out against your own KaryaYogi account and your own device or test data. It does not authorise you to access, alter, or disclose another person's data. It also cannot waive the rights of third parties, and it does not override applicable Indian law. If in doubt about whether an action is permitted, stop and email us at support@karyayogi.in before you proceed.

If a third party brings a legal action against you for work that genuinely followed this policy, tell us promptly and we will make clear that your testing was authorised.

What Is In Scope

We welcome reports about security weaknesses in the software and services we publish and control:

  • The KaryaYogi Android app, including the local AES-256 vault, the app-lock (biometric or PIN), the encrypted local backup file, and the Emergency Reset function.
  • The web workspace at my.karyayogi.in and its supporting APIs.
  • The optional encrypted cloud sync that links a device to a user's account.
  • The marketing site at karyayogi.in, for issues such as content injection or misconfiguration.

Examples of issues we want to hear about include: bypassing the app lock or vault encryption, extracting vault contents from a backup or from device storage, authentication or session flaws in the portal, access-control gaps that expose one account's data to another, injection flaws, and weaknesses in how sync data is protected in transit or at rest.

What Is Out of Scope

The following are not in scope, and testing them is not authorised under this policy:

  • Other people's data on my.karyayogi.in. Do not attempt to access, download, modify, or delete any account, workspace, or content that is not your own. If a flaw appears to expose another user's data, stop immediately, do not view or save it, and report the flaw to us.
  • Social engineering of our staff, contractors, or users — including phishing, pretexting, vishing, or any attempt to obtain credentials or access by deception.
  • Denial-of-service (DoS) and load testing — volumetric attacks, resource-exhaustion attempts, and any testing that degrades or interrupts service for other users.
  • Physical attacks against our offices, staff, or hardware.
  • Attacks that require a already-compromised device, a rooted or malware-infected phone, or physical possession of another person's unlocked device.
  • Reports from automated scanners with no demonstrated, exploitable impact; missing best-practice headers or configuration hardening with no security consequence; and issues in third-party services we do not control.

If you are unsure whether something is in scope, ask first at support@karyayogi.in.

Rules for Good-Faith Testing

To keep your testing within safe harbour, please follow these rules:

  • Test only against your own account, device, and data. Create a separate test account on the portal where you can.
  • Access only the minimum data needed to prove a vulnerability. Stop as soon as you have confirmed it.
  • Do not exfiltrate, retain, or share any data belonging to other users. Do not run destructive tests, mass-delete data, or degrade the service.
  • Do not use automated high-volume tooling against the portal or APIs.
  • Give us a reasonable period to investigate and fix an issue before you disclose it to anyone else (see below).

How to Report a Vulnerability

Send your report by email to support@karyayogi.in. A clear report helps us fix the issue faster. Where possible, please include:

  • A description of the vulnerability and the component affected (the app, the portal, sync, or the marketing site).
  • Clear, reproducible steps, including any request or response details, and the app version, device model, and OS version if relevant.
  • A realistic assessment of the impact — what an attacker could actually do.
  • Any proof-of-concept material. Please redact or avoid including real personal data of any user other than yourself.

If you need to share sensitive details securely, say so in your first email and we will agree an appropriate method with you.

What You Can Expect From Us

When you send a report to support@karyayogi.in, we will acknowledge that we received it, review it, and keep you informed of our assessment and of progress toward a fix. We will let you know when we believe the issue is resolved.

We aim to respond promptly. We deliberately do not publish fixed response or resolution timelines here, because they vary with the severity and complexity of an issue; we will set expectations with you directly on each report.

Recognition — and No Bounty

KaryaYogi does not run a paid bug-bounty programme, and we do not promise any monetary reward for a report.

What we do offer is acknowledgement. With your consent, we are happy to credit researchers who make a valid, good-faith report of a genuine security issue. If you would prefer to remain anonymous, tell us and we will respect that.

Coordinated Disclosure — Do Not Disclose Until Fixed

We ask you to practise coordinated disclosure: please do not publish, share, or otherwise disclose a vulnerability, or any details that would help others exploit it, until we have had a fair opportunity to investigate and release a fix, and until we have confirmed with you that it is resolved.

If you believe an issue is not being addressed, or you feel public disclosure is necessary in the wider interest, contact us first at support@karyayogi.in so we can agree a reasonable timeline together. Premature disclosure that puts users at risk falls outside the good-faith testing this policy protects.

How This Fits Our Data Protection Duties

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), KaryaYogi acts as the Data Fiduciary for personal data processed through KaryaYogi, and you, as a user, are the Data Principal. Protecting that data with reasonable security safeguards is one of our duties under the Act, and responsible disclosure directly supports it.

By design, the app is offline-first: the tools work with the SIM removed, your data is held in an AES-256 local vault, and no account is needed to use the app. Cloud sync is optional, encrypted, and hosted in India, keyed to your account. This means most of your data stays on your device unless you choose to sync it.

If a security issue you report involves a breach affecting users' personal data, we will handle it in line with our obligations under the DPDP Act, including notifying affected users and the authorities where the law requires. Your careful, good-faith reporting helps us meet that responsibility.

Contact and Related Pages

For all security reports and questions about this policy, write to support@karyayogi.in.

For privacy questions and to exercise your rights over your personal data, contact support@karyayogi.in. To raise a formal grievance, contact support@karyayogi.in.

If you need a postal address or the name of a responsible officer for a formal matter, that is available on request via the email addresses above.

KaryaYogi

A private planning and productivity workbench for officers of the Government of India. Offline-first, India-hosted, DPDP-ready.

MADE IN INDIA

Tools

  • Leave & Calendar
  • Pay & Money
  • Service & Benefits
  • Planning & Productivity
  • Wellness
  • Personal Utility
  • Privacy & Settings

App

  • App tour
  • Offline mode
  • Sync & backup
  • Web workspace
  • What’s New

Security

  • Encryption
  • Privacy by design
  • Trust certificate
  • Disclosure

Legal

  • Privacy Policy
  • Delete Account
  • Terms of Service
  • DPDP compliance
  • Grievance
  • Official sources

© 2026 KaryaYogi · Independent and unofficial

KaryaYogi is a private planning aid. It is not affiliated with, endorsed by, or a product of the Government of India, and it does not replace eOffice, HRMS or any authorised system of record. Government rules, pay rates and entitlements referenced here are published by the Department of Personnel & Training, the Department of Expenditure and India Code — always verify against the current official notification. Official sources & disclaimer